PkgRadar

npm · registry.npmjs.org

@nanocollective/nanocoder

Js Hidden Powershell

Why PkgRadar flagged 1.26.0

SeveritySignalEvidence
highJs Hidden Powershellpackage/dist/mcp/transport-factory.js

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
1.26.0Review312026-06-20
1.28.0Review312026-06-20
1.26.1Low risk02026-05-27
1.27.0Low risk02026-05-27

Block this in CI

PkgRadar gates @nanocollective/nanocoder (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @nanocollective/[email protected]